Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-63848 — CVE disclosure for stored cross-site scripting (XSS) in SWISH Prolog up to v2.2.0, enabling arbitrary code execution and account takeover via crafted web IDE notebooks. | Kitploit
Tools/GitHubGitHub/codermohammed1/cve-2025-63848
Vulnerability AnalysisExploitationWeb SecurityLearning & EducationCurated Resources
GitHubcodermohammed1/cve-2025-63848

CVE-2025-63848

CVE disclosure for stored cross-site scripting (XSS) in SWISH Prolog up to v2.2.0, enabling arbitrary code execution and account takeover via crafted web IDE notebooks.

View Repository
710 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-63848

swish-prolog cve

Stored cross site scripting (xss) vulnerability in SWISH prolog thru 2.2.0 allowing attackers to execute arbitrary code via crafted web IDE notebook.


Impact

One click Account takeover.


Mitigation

Upgrade to the latest version to mitigate the ATO.

https://github.com/SWI-Prolog/swish/commit/4fb6acb97bedf993ec406a2ef324eeb2a16c49e3

Download Tool